Aim是美国Aim开源的一个易于使用和高性能的开源实验跟踪器。 Aim 3.22.0版本存在访问控制错误漏洞,该漏洞源于AimQL查询语言使用过时的safer_getattr函数,未保护str.format_map方法,可能导致服务器端秘密泄露或任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| aimhubio | aimhubio/aim | unspecified ~ latest | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-0189 | Denial of Service in aimhubio/aim | |
| CVE-2025-0190 | Denial of Service in aimhubio/aim | |
| CVE-2024-12777 | Denial of Service in aimhubio/aim | |
| CVE-2024-12778 | Denial of Service in aimhubio/aim | |
| CVE-2024-6851 | Arbitrary File Deletion in aimhubio/aim | |
| CVE-2024-6483 | Arbitrary File/Directory Deletion in aimhubio/aim | |
| CVE-2024-6829 | Arbitrary File Overwrite through tarfile-extraction in aimhubio/aim | |
| CVE-2024-7760 | CSRF in aimhubio/aim | |
| CVE-2024-8061 | Denial of Service in aimhubio/aim | |
| CVE-2024-8769 | Arbitrary File Deletion via Relative Path Traversal in aimhubio/aim | |
| CVE-2024-8101 | Stored XSS in aimhubio/aim | |
| CVE-2024-10110 | Denial of Service in aimhubio/aim |
No comments yet